Find & Ask New York › this rule

18 NYCRR 521-1.4 — Compliance Program Requirements (OMIG)

New YorkregulationNew York State Office of the Medicaid Inspector General (OMIG)· effective 2022-12-28

What this rule requires your agency to do

  • 1The required provider shall designate a compliance committee comprised at a minimum of senior managers, operating under a charter (reviewed at least annually), meeting no less frequently than quarterly, and reporting directly and accountable to the chief executive and governing body (subd. c).(18 NYCRR 521-1.4 — Compliance Program Requirements (OMIG))
  • 2The required provider shall establish procedures to promptly investigate, document, and correct compliance issues to prevent recurrence, and where it identifies credible evidence that a state or federal law, rule or regulation has been violated, shall promptly report such violation to the appropriate governmental entity where reporting is otherwise required by law (subd. h).(18 NYCRR 521-1.4 — Compliance Program Requirements (OMIG))
  • 3The required provider shall designate a compliance officer who is the focal point for day-to-day operation of the compliance program, reports directly and is accountable to the chief executive (or a designated senior manager), reports to the governing body and compliance committee no less frequently than quarterly, is allocated sufficient staff and resources, and has access to all relevant records, facilities, and individuals (subd. b).(18 NYCRR 521-1.4 — Compliance Program Requirements (OMIG))
  • 4The required provider shall establish confidential lines of communication accessible to all affected individuals and MA recipients, including a method for anonymous reporting of potential fraud, waste, abuse and compliance issues directly to the compliance officer, and shall protect the confidentiality of persons reporting (subd. e).(18 NYCRR 521-1.4 — Compliance Program Requirements (OMIG))
  • 5The required provider shall establish and implement an effective compliance training and education program covering the specified topics; the compliance officer and all affected individuals shall complete it no less frequently than annually and promptly upon hiring; and the provider shall develop and maintain a training plan tracking topics, timing, attendance, and effectiveness (subd. d).(18 NYCRR 521-1.4 — Compliance Program Requirements (OMIG))
  • 6The required provider shall establish and enforce written disciplinary standards fairly and consistently across all levels of personnel, with escalating sanctions for non-compliance and more significant sanctions for intentional or reckless behavior (subds. a(2)(viii), f).(18 NYCRR 521-1.4 — Compliance Program Requirements (OMIG))
  • 7The required provider shall maintain written policies, procedures, and standards of conduct that are available, accessible, and applicable to all affected individuals; that articulate the provider's obligation to comply with all applicable federal and state standards and identify laws/regulations applicable to its risk areas; and it shall review them at least annually to confirm implementation, adherence, effectiveness, and needed updates (subd. a).(18 NYCRR 521-1.4 — Compliance Program Requirements (OMIG))
  • 8The required provider shall implement an effective system of routine internal (and, as appropriate, external) auditing and monitoring focused on identified risk areas, document and share results with the compliance committee and governing body, report and return overpayments in accordance with Subpart 521-3, and review the OMIG Exclusion List and the federal OIG List of Excluded Individuals and Entities at least every thirty (30) days to determine the exclusion status of affected individuals (subd. g).(18 NYCRR 521-1.4 — Compliance Program Requirements (OMIG))

Applies to: personal care

Specifies the mandatory elements every required Medicaid provider's compliance program must contain — written policies and standards of conduct, a compliance officer, a compliance committee, training and education, confidential lines of communication with anonymous reporting, disciplinary standards, auditing and monitoring (including monthly exclusion screening), and a system for responding to compliance issues.

Regulatory information, not legal advice — always confirm against the cited official source. Verification reduces error; it does not certify compliance.